Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. Security groups vs. a traditional firewall: what's the difference

Security groups vs. a traditional firewall: what's the difference

Applies to General concept, cloud platformsAudience All customersLast reviewed September 2026

Quick answer

A security group is filtering rules attached directly to one server or a set of servers, managed at the cloud platform level. A traditional network firewall sits in front of a whole network segment instead of a single instance. Both usually work on the same underlying idea, a stateful rule set that tracks connections and automatically allows return traffic, but they operate at a different layer of the network.

On this page
  • What a security group is
  • What a traditional firewall is
  • Stateful vs. stateless: the concept behind both
  • Why this distinction matters

The term "security group" shows up across most major cloud platforms to describe rules that travel with a specific server rather than sitting in front of a whole network. It's worth understanding the distinction even if you never touch a platform that uses that exact name, because the underlying idea, filtering attached to an instance versus filtering attached to a network boundary, comes up under other names too.

What a security group is

A security group is a set of allow rules that a cloud platform lets you attach directly to a server, or to a group of servers that share the same role. Instead of routing traffic through a separate appliance, the platform enforces the rules at the point where the instance's network interface meets the rest of the network. Add a server to a security group, and its inbound and outbound traffic gets filtered according to that group's rules, no separate device to configure.

Security groups are typically stateful by default. If a rule allows an outbound connection, the platform automatically permits the matching return traffic back in, without needing a separate inbound rule for it. That's a deliberate simplification: you write the rule for the direction that matters to you, and the platform handles the reply traffic on its own.

What a traditional firewall is

A traditional network firewall, sometimes called a perimeter firewall, sits in front of a whole network segment rather than being attached to one instance. Every server behind it shares the same gateway and the same set of rules, unless you carve out more specific exceptions. Worldstream's own Firewall product in Portal is this kind of shared, per-region gateway: you create one firewall per region and attach your internal networks to it, and its rule sets live on separate NAT Rules and Firewall Rules tabs. See Firewall basics in Portal for how that's set up.

Architecturally, that's the core difference. A security group is instance-level and travels with the server. A perimeter firewall is network-level and applies uniformly to everything behind it.

Stateful vs. stateless: the concept behind both

Whether you're looking at a security group or a perimeter firewall, the rules underneath tend to work one of two ways:

  • Stateful: the firewall tracks active connections. Allow a connection out, and the return traffic is automatically permitted back in, no matching inbound rule required. This is the more common default on modern platforms because it's simpler to reason about, you write a rule per direction of traffic you actually want to initiate.
  • Stateless: every packet is evaluated on its own, with no memory of what came before. To let a connection work in both directions, you need explicit rules for the outbound leg and the inbound leg separately. This is less common as a default today but still shows up in some lower-level network access control lists.

Most security groups and most modern perimeter firewalls default to stateful behaviour. The stateful/stateless distinction is a separate axis from the instance-level/network-level distinction covered above, a firewall can be perimeter-level and still be stateful, and in practice most are.

Why this distinction matters

Understanding the difference helps when you're reading documentation from different platforms or moving workloads between them. A platform that talks about "security groups" is describing rules that live with the instance. A platform that talks about a "firewall" in the traditional sense is usually describing something that sits in front of a network segment. Neither is inherently better, they solve filtering at different layers, and many setups use both: a perimeter firewall for broad network boundaries, plus finer-grained rules closer to individual workloads.

Related articles

  • Firewall basics in Portal
  • Understanding load balancing: what it does and how it decides
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure